Datasheet | Check Point SASE

Datasheet | Check Point SASE

Secure hybrid work and cloud access with Check Point SASE. AI-powered Zero Trust, SaaS security, and SD-WAN deliver fast, unified cyber security.

Datasheet | Check Point SASE

Check Point SASE

Unified Network Security for the AI Age

Check Point SASE Unified Network Security for the AI Age

Check Point SASE | 1

Security Beyond the Perimeter

Organizations are navigating fundamental shifts in how users access applications and data. Cloud services, SaaS, AI adoption, and hybrid work are creating a distributed, borderless environment that traditional security can't protect.

The result is a fragmented network architecture. It opens security gaps and adds operational complexity across three fronts.

89% 88% 75% of organizations use two or more public cloud services.1

support hybrid work, requiring least-privileged access across cloud, SaaS, and data centers.2

of global knowledge workers use GenAI at work, expanding the attack surface.3

At the same time that legacy network borders break down, the overall volume and sophistication of cyberattacks continue to rise. AI is further fueling this trend by helping attackers automate campaigns and rapidly evolve malware.

SASE has emerged as the architectural framework that addresses this fragmented landscape and expanding threat environment.

By converging network and security functions into a cloud-delivered platform, the SASE approach enables organizations to block threats that isolated point solutions miss, accelerate incident response, and improve the end user experience.

Flexera, “Cloud computing trends: Flexera 2024 State of the Cloud Report,” 2024, 
 https://www.flexera.com/blog/finops/cloud-computing-trends-flexera-2024-state-of-the-cloud-report/

Robert Half, “Remote Work Statistics and Trends for 2025,” 2025, 
 https://www.roberthalf.com/us/en/insights/research/remote-work-statistics-and-trends

Microsoft, “AI at Work Is Here. Now Comes the Hard Part,” 2024, 
 https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part

Check Point SASE | 1

Organizations are navigating fundamental shifts in how users access applications and data. Cloud services, SaaS, AI adoption, and hybrid work are creating a distributed, borderless environment that

traditional security can't protect.

The result is a fragmented network architecture. It opens security gaps and adds operational complexity across three fronts.

Security Beyond the Perimeter

At the same time that legacy network borders break down, the overall volume and sophistication of

cyberattacks continue to rise. AI is further fueling this trend by helping attackers automate

campaigns and rapidly evolve malware.

SASE has emerged as the architectural framework that addresses this fragmented landscape and

expanding threat environment.

By converging network and security functions into a cloud-delivered platform, the SASE approach

enables organizations to block threats that isolated point solutions miss, accelerate incident

response, and improve the end user experience.

Flexera, "Cloud computing trends: Flexera 2024 State of the Cloud Report," 2024,

https://www.flexera.com/blog/finops/cloud-computing-trends-flexera

-2024-state-of-the-cloud-report/  Robert Half, "Remote Work Statistics and Trends for 2025," 2025, https://www.roberthalf.com/us/en/insights/research/remote-work-statistics-and-trends Microsoft, "AI at Work Is Here. Now Comes the Hard Part," 2024, https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part

89% of organizations use two or

more public

cloud services.1

88% support hybrid work,

requiring least-privileged

access across cloud, SaaS,

and data centers.2

75% of global knowledge workers

use GenAI at work,

expanding the attack

surface.3

https://www.flexera.com/blog/finops/cloud-computing-trends-flexera-2024-state-of-the-cloud-report/ https://www.roberthalf.com/us/en/insights/research/remote-work-statistics-and-trends https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part

Check Point SASE | 2

Meet Check Point SASE

Unified 10x Faster Internet Security, Zero Trust Access, SaaS Security, and SD-WAN

BENEFITS

Single-vendor SASE that consolidates diverse security capabilities into one streamlined platform

Blazing-fast secure internet access for remote users and branch offices

Zero Trust Access with full mesh connectivity between users, branches, and applications

Powerful SaaS Security with inline and API-based enforcement for complete visibility, data protection, compliance and posture management, and threat prevention across your SaaS ecosystem

Workforce AI Security for end-to-end discovery, governance, and runtime protection of employee AI usage across browser, desktop apps, AI agents, and MCPs — with AI- powered contextual DLP, prompt-level visibility, and granular policy enforcement

Optimized SD-WAN connectivity with full branch-level security and leading threat prevention

Fast deployment and intuitive administration

Backed by Check Point ThreatCloud AI our global threat intelligence platform that aggregates data from millions of sensors worldwide and 50+ AI engines to update protections in real time

Check Point SASE | 2

BENEFITS

Meet Check Point SASE  Unified 10x Faster Internet Security, Zero Trust Access, SaaS Security, and SD-WAN

Single-vendor SASE

Single-vendor SASE that consolidates diverse security capabilities into one streamlined platform

Blazing-fast secure internet access

Zero Trust Access

Zero Trust Access with full mesh connectivity between users, branches, and applications

Powerful SaaS Security

Powerful SaaS Security with inline and API-based enforcement for complete visibil

ity, data protection, compliance and posture management, and threat prevention across your SaaS ecosystem

Blazing-fast secure internet access

Workforce AI Security for end-to-end discovery, governance, and runtime protec

tion of employee AI usage across browser, desktop apps, AI agents, and MCPs - with AI-powered contextual DLP, prompt-level visibility, and granular policy enforcement

Optimized SD-WAN connectivity with full branch-level

security and leading threat prevention

Zero Trust Access

Zero Trust Access

Zero Trust Access  Backed by Check Point ThreatCloud AI our globa

l threat intelligence platform that aggregates data from millions of sensors wor

ldwide and 50+ AI engines to update protections in real time

Check Point SASE | 3

While organizations are shifting to SASE, their current solutions break the user experience with slow connections and complex management.

Offering a game-changing alternative, Check Point SASE delivers 10x faster internet security combined with full mesh Zero Trust Access, SaaS Security, and optimized SD-WAN performance.

With a local browsing experience supporting tighter security and privacy, Check Point SASE boasts innovative on-device network protections and secures any enterprise application by integrating with your existing identity providers to enforce granular access policies for everyone: employees, contractors, and third parties. Its SD-WAN solution unifies industry-leading threat prevention with optimized internet and network connectivity, ensuring uninterrupted web conferencing thanks to seamless link failover and a built-in steering policy for over 10,000 applications.

The Check Point SASE platform reduces operational friction and closes security gaps that are common to fragmented stacks.

Blazing-Fast Secure Internet Access

Check Point SASE Internet Access delivers 10x faster performance by fundamentally redesigning how traffic is secured. Unlike traditional SASE solutions that suffer from cloud backhauling, our hybrid architecture can inspect traffic locally on the device, thereby optimizing speed and privacy while maintaining rigorous security enforcement.

Hybrid Architecture:

Delivers on-device inspection to bypass unnecessary cloud processing for blazing-fast browsing, and a localized experience that respects data residency requirements and privacy.

Comprehensive Threat Prevention

Delivers unified security including web filtering, malware protection, and advanced threat prevention that moves with the user, offering consistent protection regardless of location.

Browser security

Integrated protection against phishing, malicious downloads, corporate password reuse, and risky search results.

Check Point SASE | 3

While organizations are shifting to SASE, their current solutions break the user experience with slow

connections and complex management.

Offering a game-changing alternative, Check Point SASE delivers 10x faster internet security

combined with full mesh Zero Trust Access, SaaS Security, and optimized SD-WAN performance.

With a local browsing experience supporting tighter security and privacy, Check Point SASE boasts

innovative on-device network protections and secures any enterprise application by integrating with

your existing identity providers to enforce granular access policies for everyone: employees,

contractors, and third parties. Its SD-WAN solution unifies industry-leading threat prevention with

optimized internet and network connectivity, ensuring uninterrupted web conferencing thanks to

seamless link failover and a built-in steering policy for over 10,000 applications.

The Check Point SASE platform reduces operational friction and closes security gaps that are

common to fragmented stacks.

Check Point SASE Internet Access delivers 10x faster performance by fundamentally redesigning how

traffic is secured. Unlike traditional SASE solutions that suffer from cloud backhauling, our hybrid

architecture can inspect traffic locally on the device, thereby optimizing speed and privacy

while maintaining rigorous security enforcement.

Blazing-Fast Secure Internet Access

Hybrid Architecture:

Delivers on-device inspection

to bypass unnecessary cloud

processing for blazing-fast

browsing, and a localized

experience that respects data

residency requirements and

privacy.

Comprehensive Threat Prevention

Delivers unified security

including web filtering, malware

protection, and advanced threat

prevention that moves with the

user, offering consistent

protection regardless of location.

Browser security

Integrated protection

against phishing, malicious

downloads, corporate

password reuse,

and risky search results.

Check Point SASE | 4

Workforce AI Security

Secure every AI interaction across browser, desktop apps, code assistants, AI agents, and MCPs — with contextual visibility, granular policy, and real-time protection.

GenAI accelerates business, but it also creates blind spots that no legacy DLP was built to see. Employees move sensitive data through prompts, uploads, and SaaS integrations. Shadow tools appear faster than security teams can catalog them. Autonomous agents and MCP-connected workflows act on corporate resources with no clear ownership or audit trail.

Workforce AI Security from Check Point SASE closes these gaps.

Discover every AI app and tool in use

Classify prompt content — including files — and break down activity by application, session, and user.

Understand user intent to assess risk: each interaction is scored and described with the user action, data source, and context.

Surface adoption trends and identify which applications drive AI use by area of risk.

Detect AI usage inside connected SaaS platforms for consistent governance in a single dashboard.

Browse a catalog of 4,000+ GenAI applications and search any app, even those not yet used in your organization.

See every AI tool, agent, and action across web and desktop apps, SaaS integrations, browser extensions, code assistants, AI agents, and MCPs.

Inspect MCP and agent traffic to prevent risky tool use and data exposure.

Check Point SASE | 4

Secure every AI interaction across browser, desktop apps, code assistants, AI agents, and MCPs - with contextual visibility, granular policy, and real-time protection.

GenAI accelerates business, but it also creates blind spots that no legacy DLP was built to see. Employees move sensitive data through prompts, uploads, and SaaS integrations. Shadow tools

appear faster than security teams can catalog them. Autonomous agents and MCP-connected workflows act on corporate resources with no clear ownership or audit trail.

Workforce AI Security from Check Point SASE closes these gaps.

Workforce AI Security

Discover every AI app and tool in use

Classify prompt content -

including files - and break

down activity by application,

session, and user.

Understand user intent to

assess risk: each interaction is

scored and described with the

user action, data source, and

context.

Detect AI usage inside

connected SaaS platforms for

consistent governance in a

single dashboard.

Surface adoption trends

and identify which applications

drive AI use by area of risk.

Browse a catalog of 4,000+

GenAI applications and search

any app, even those not yet used

in your organization.

Inspect MCP and agent traffic to

prevent risky tool use and data

exposure.

See every AI tool, agent, and action across web and desktop apps, SaaS integrations,

browser extensions, code assistants, AI agents, and MCPs.

Check Point SASE | 5

Govern with granular access and security controls

Classify conversational data by category

Set granular policy controls per application, including copy/paste rules and in-prompt sensitive data restrictions

Apply different policies for managed and unmanaged apps

Block employee access to unauthorized AI apps, and set rules that prevent risky connections between AI tools and corporate resources

Govern third-party integrations with SaaS platforms

Govern agent behavior and tool access—define explicit policies that control which tools agents can use, what operations they can perform, and on which platforms

Protect with AI-powered contextual DLP

Redact sensitive data in real time and replace it with labeled placeholders for credentials, PII, and more

Inline prompt protection, file and image redaction, and OCR catch what pattern-based DLP misses

Interactive action validation wizard reduces data loss risk without blocking legitimate work

Runtime controls block risky agentic actions on employee devices

Audit trails and customizable reports support GDPR, HIPAA, and EU AI Act compliance

Deploy fast, protect from day one

Deploy quickly across browsers and devices — no complex setup, no downtime

Gain full visibility into every employee AI interaction, including shadow apps, and enforce policy fast

Check Point SASE | 5

Classify conversational data by category

Set granular policy controls per application, including copy/paste rules and in-prompt sensitive

data restrictions

Apply different policies for managed and unmanaged apps

Block employee access to unauthorized AI apps, and set rules that prevent risky connections

between AI tools and corporate resources

Govern third-party integrations with SaaS platforms

Govern agent behavior and tool access-define explicit policies that control which tools agents can

use, what operations they can perform, and on which platforms

Redact sensitive data in real time and replace it with labeled placeholders for credentials, PII, and

more

Inline prompt protection, file and image redaction, and OCR catch what pattern-based DLP

misses

Interactive action validation wizard reduces data loss risk without blocking legitimate work

Runtime controls block risky agentic actions on employee devices

Audit trails and customizable reports support GDPR, HIPAA, and EU AI Act compliance

Deploy quickly across browsers and devices - no complex setup, no downtime

Gain full visibility into every employee AI interaction, including shadow apps, and enforce

policy fast

Protect with AI-powered contextual DLP

Deploy fast, protect from day one

Govern with granular access and security controls

Check Point SASE | 6

Full Mesh Zero Trust Access

Check Point SASE Private Access replaces legacy VPNs and fragmented access tools with a Full Mesh Zero Trust architecture. Instead of just connecting users to apps, Check Point SASE creates a global, software-defined network in minutes connecting users, sites, clouds, and resources with effective Zero Trust access policies.

Identity-Centric Access: Apply least privileged access to any enterprise resource by integrating your existing Identity Providers (IdP) to enforce policies based on user role, groups, and context that accommodates employees, contractors, and partners alike

Agentless & Managed Access: Secure BYOD, partners, and consultants with frictionless agentless web access

Contextual Device Posture: Validate device health (OS version, antivirus status, and more) before granting access and during connections, ensuring only safe devices are allowed on the network

Reliable, high-performance connectivity: Delivers a superior user experience with low- latency connectivity over a full mesh global private backbone of 80+ PoPs

Seamless deployment: Create networks and bring them online quickly to interconnect your sites, data centers, clouds, and users via an intuitive cloud console

SaaS Security and CASB

Check Point SASE delivers comprehensive SaaS security that combines inline and API-based enforcement for end-to-end visibility, threat protection, compliance and posture management, and data protection across your entire SaaS ecosystem.

Inline Controls

Enforce real-time security policies across web and SaaS traffic with Check Point SASE's inline inspection engine. SaaS Application Control identifies and manages access to more than 10,000 cloud applications, enabling granular allow, block, or restrict actions based on corporate policy and compliance requirements.

Check Point SASE | 6

Check Point SASE Private Access replaces legacy VPNs and fragmented access tools with a Full Mesh Zero Trust architecture. Instead of just connecting users to apps, Check Point SASE creates a global,

software-defined network in minutes connecting users, sites, clouds, and resources with effective Zero Trust access policies.

Full Mesh Zero Trust Access

Check Point SASE delivers comprehensive SaaS security that combines inline and API-based enforcement for end-to-end visibility, threat protection, compliance and posture management, and

data protection across your entire SaaS ecosystem.

Enforce real-time security policies across web and SaaS traffic with Check Point SASE's inline inspection engine. SaaS Application Control identifies and manages access to more than 10,000 cloud

applications, enabling granular allow, block, or restrict actions based on corporate policy and compliance requirements.

SaaS Security and CASB

Inline Controls

Identity-Centric Access: Apply least privileged access to any

enterprise resource by integrating your existing Identity Providers (IdP) to enforce polic

ies based on user role, groups, and context that accommodates employees, contractors, and partners alike

Single-vendor SASE

Blazing-fast secure internet access

Agentless & Managed Access: Secure BYOD, partners, and consultants with frictionless agentless web access

Contextual Device Posture: Validate device health (OS vers

ion, antivirus status, and more) before granting access and during connections, ensu

ring only safe devices are allowed on the network

Zero Trust Access

Reliable, high-performance connectivity: Deli

vers a superior user experience with low-latency connectivity over a full mesh global private backbone of 80+ PoPs

Powerful SaaS Security

Blazing-fast secure internet access

Seamless deployment: Create networks and bring them online quickly to interconnect your sites, data centers, clouds, and users via an intuitive cloud console

Check Point SASE | 7

Tenant restrictions let you limit access to only your organization's sanctioned SaaS tenants — preventing users from logging into personal or unauthorized instances of apps like Microsoft 365 or Google Workspace, a common vector for data exfiltration.

Inline DLP inspects uploads and posts in real time using Check Point's AI-powered classification engine with 800+ predefined data types, while inline Threat Prevention scans downloads and web content for known and unknown malware, powered by ThreatCloud AI.

API-Based (Out-of-Band) DLP & Threat Prevention

Go beyond inline inspection with out-of-band, API-based scanning that protects data at rest (and in- SaaS activity such as sharing permission changes) across your SaaS environment — no agent required. Check Point SASE connects directly to your SaaS platforms to continuously scan files, messages, and unstructured content such as Jira tickets, Teams messages, and Slack conversations for sensitive data and threats.

Data Loss Prevention:

Detects and prevents sensitive data exposure at rest with AI-powered classification across 800+ predefined data types including PII, financial data, credentials, intellectual property, and custom types. Over-sharing protection continuously monitors sharing permissions and automatically remediates policy violations, including revocation of risky access.

Threat Prevention:

Scans data at rest for known and unknown malware across SaaS environments, powered by Check Point ThreatCloud AI. Automated response options enable immediate removal of malicious content.

Supported SaaS Applications:

Google Workspace, Jira, Salesforce, Microsoft (OneDrive, SharePoint, Teams), Dropbox, Box, Slack, and GitHub, with more applications coming soon.

Check Point SASE | 7

Tenant restrictions let you limit access to only your organization's sanctioned SaaS tenants -

preventing users from logging into personal or unauthorized instances of apps like Microsoft

365 or Google Workspace, a common vector for data exfiltration.

Inline DLP inspects uploads and posts in real time using Check Point's AI-powered classification

engine with 800+ predefined data types, while inline Threat Prevention scans downloads and web

content for known and unknown malware, powered by ThreatCloud AI.

Go beyond inline inspection with out-of-band, API-based scanning that protects data at rest (and in-

SaaS activity such as sharing permission changes) across your SaaS environment - no

agent required. Check Point SASE connects directly to your SaaS platforms to continuously scan files,

messages, and unstructured content such as Jira tickets, Teams messages, and Slack conversations

for sensitive data and threats.

API-Based (Out-of-Band) DLP & Threat Prevention

Data Loss Prevention:

Detects and prevents sensitive data exposure at rest with AI-powered classification

across 800+ predefined data types including PII, financial data, credentials,

intellectual property, and custom types. Over-sharing protection

continuously monitors sharing permissions and automatically remediates policy

violations, including revocation of risky access.

Threat Prevention:

Scans data at rest for known and unknown malware across SaaS environments,

powered by Check Point ThreatCloud AI. Automated response options enable

immediate removal of malicious content.

Supported SaaS Applications:

Google Workspace, Jira, Salesforce, Microsoft (OneDrive, SharePoint, Teams),

Dropbox, Box, Slack, and GitHub, with more applications coming soon.

Check Point SASE | 8

AI-Powered Data Classification

Check Point's DLP engine natively incorporates AI/ML-driven capabilities for superior classification accuracy. A multilayered architecture combines private, locally hosted LLMs for semantic data labeling with optimized lightweight ML classifiers that use NLP, Named Entity Recognition (NER), and neural network models to identify sensitive data such as PII and PHI. An ML-driven context classification layer around traditional regex and keyword matches significantly improves precision and reduces false positives.

SaaS Security Posture Management

Automatically discover and map your entire SaaS ecosystem, including every application, plugin, and API integration.

Shadow SaaS Discovery:

Expose hidden risks by mapping your organization's complete SaaS interconnectivity.

Configuration Risk Remediation

Shrink your attack surface with continuous SaaS configuration monitoring, alerts, and remediation for misconfigurations and compliance violations.

Application Control

Allow or disallow access to specific SaaS applications based on corporate policies.

Identity & Anomaly Detection

AI-powered detection of data theft, supply chain attacks, and account takeover through behavioral analysis, threat intelligence, and historical SaaS activity data.

Compliance Readiness

Security posture assessment aligned with NIST best practices that map to common regulatory requirements (e.g. HIPAA, SOC 2, GDPR), helping maintain an audit- ready posture.

SaaS-to-SaaS Connection Threat Prevention

Alert and block third-party SaaS connections that put your SaaS environment at risk.

Check Point SASE | 8

Check Point's DLP engine natively incorporates AI/ML-driven capabilities for superior classification

accuracy. A multilayered architecture combines private, locally hosted LLMs for semantic data

labeling with optimized lightweight ML classifiers that use NLP, Named Entity Recognition (NER), and

neural network models to identify sensitive data such as PII and PHI. An ML-driven context

classification layer around traditional regex and keyword matches significantly improves precision

and reduces false positives.

Automatically discover and map your entire SaaS ecosystem, including every application, plugin, and

API integration.

AI-Powered Data Classification

SaaS Security Posture Management

Shadow SaaS Discovery:

Expose hidden risks by

mapping your organization's

complete SaaS

interconnectivity.

Configuration Risk Remediation

Shrink your attack surface with

continuous SaaS configuration

monitoring, alerts, and

remediation for misconfigurations

and compliance violations.

Application Control

Allow or disallow access to

specific SaaS applications

based on corporate policies.

Identity & Anomaly Detection

AI-powered detection of data

theft, supply chain attacks, and

account takeover through

behavioral analysis, threat

intelligence, and historical

SaaS activity data.

Compliance Readiness

Security posture assessment

aligned with NIST best practices

that map to common regulatory

requirements (e.g. HIPAA, SOC 2,

GDPR), helping maintain an audit-

ready posture.

SaaS-to-SaaS Connection Threat Prevention

Alert and block third-party

SaaS connections that put your

SaaS environment at risk.

Check Point SASE | 9

Advanced Threat Prevention

Check Point SASE blocks known and unknown threats before they reach your users or data. By leveraging Check Point’s ThreatCloud AI we deliver the industry’s best catch rate (99%) with near- zero false positives.

Threat Emulation (sandboxing): Identifies unknown malware by running suspicious files in a controlled virtual environment.

Data Loss Prevention (DLP): A unified DLP engine prevents sensitive corporate data from being uploaded to unauthorized web or cloud environments.

Anti-Bot Protection: Detects and blocks outbound traffic from infected devices to botnet command-and-control servers, neutralizing botnet threats.

Optimized Performance: Fast, seamless protection that preserves performance even for remote workers.

Malicious and Risky SaaS Apps Detection: AI-powered monitoring to proactively detect malicious and high-risk SaaS. Gain full visibility into app usage, assess risk in real time, and enforce granular controls to prevent data exposure and unauthorized access.

Check Point SASE | 9

Check Point SASE blocks known and unknown threats before they reach your users or data. By leveraging Check Point's ThreatCloud AI we deliver the industry's best catch rate (99%) with near-

zero false positives.

Advanced Threat Prevention

Single-vendor SASE  Threat Emulation (sandboxing): Identifies unknown

malware by running suspicious files in a controlled virtual environment.

Blazing-fast secure internet access

Data Loss Prevention (DLP): A unified DLP engine prevents sensitive corporate data from being uploaded to unauthorized web or cloud environments.

Zero Trust Access  Anti-Bot Protection: Detects and blocks outbound traffic from infect

ed devices to botnet command-and-control servers, neutralizing botnet threats.

Powerful SaaS Security

Optimized Performance: Fast, seamless protection that preserves performance even for remote workers.

Blazing-fast secure internet access  Malicious and Risky SaaS Apps Detecti

on: AI-powered monitoring to proactively detect malicious and high-risk SaaS. Gain full visibi

lity into app usage, assess risk in real time, and enforce granular controls to prevent data exposure and unauthorized access.

Check Point SASE | 10

Enterprise Browser

For organizations that require secure access and advanced protection for unmanaged devices, Check Point Enterprise Browser solves this “BYOD Gap” by creating a secure, isolated workspace on any device. It eliminates the need for a persistent agent, allowing you to safely onboard contractors and partners while still enforcing security posture, controlling data, and preventing lateral movement.

Data Isolation & Auto-Wipe Agentless Posture Validation

Isolates corporate apps and data from the host device, preventing unauthorized data transfers. When the session ends, critical corporate data is wiped from the device.

Verifies the security posture of unmanaged devices before granting access, despite the absence of a persistent agent.

Integrated DLP Controls

Prevents unauthorized data exfiltration via downloads, copy- paste, printing, or screen captures, with options such as on-screen watermarks.

Full Session Recording and Auditing

Provides complete visibility and reporting for user actions within the browser.

SD-WAN Unified with Industry-Best Security

Check Point SD-WAN unifies the best security with optimized internet and network connectivity, ensuring uninterrupted web conferencing thanks to seamless link failover and an automated steering policy, combined with robust management and site protection.

01 02 03 Uninterrupted User Experience: Ensures smooth web conferencing with sub- second WAN link failover with support for broadband internet, 5G cellular, and MPLS connections

Intelligent Path Optimization: Routing for 10,000+ applications and users, with auto-steering based on link health including jitter, packet loss, latency

Unified Branch Security: 
 Zero-touch provisioning with a full branch-level security stack and industry-leading threat prevention

Check Point SASE | 10

For organizations that require secure access and advanced protection for unmanaged devices, Check Point Enterprise Browser solves this "BYOD Gap" by creating a secure, isolated workspace on any

device. It eliminates the need for a persistent agent, allowing you to safely onboard contractors and partners while still enforcing security posture, controlling data, and preventing lateral movement.

Enterprise Browser

Check Point SD-WAN unifies the best security with optimized internet and network connectivity, ensuring uninterrupted web conferencing thanks to seamless link failover and an automated steering

policy, combined with robust management and site protection.

SD-WAN Unified with Industry-Best Security

Data Isolation & Auto-Wipe

Isolates corporate apps and

data from the host device,

preventing unauthorized data

transfers. When the session

ends, critical corporate data is

wiped from the device.

Agentless Posture Validation

Verifies the security posture of

unmanaged devices before

granting access, despite the

absence of a persistent agent.

Integrated DLP Controls

Prevents unauthorized data

exfiltration via downloads, copy-

paste, printing, or screen

captures, with options such as

on-screen watermarks.

Full Session Recording and Auditing

Provides complete visibility and

reporting for user actions within

the browser.

01 Uninterrupted User

Experience: Ensures smooth

web conferencing with sub-

second WAN link failover with

support for broadband internet, 5G

cellular, and MPLS connections

02 Intelligent Path

Optimization: Routing for

10,000+ applications and users,

with auto-steering based on

link health including jitter,

packet loss, latency

03 Unified Branch Security:

Zero-touch provisioning with

a full branch-level securit

y stack and industry-leadin

g threat prevention

Check Point SASE | 11

Check Point SASE Feature Overview

Feature Description

Zero Trust Network Access / Private Access

Network access Supports all protocols, full mesh access in any direction, all connections subject to policy with posture and identity

Agentless web access  Supported with reverse proxy, option for URL alias and customer certificate

Agentless enterprise browser  Zero Trust access for unmanaged devices with corporate data sandboxing and DLP protections including session recording and watermarking

Agentless RDP access  Web Interface (HTML RDP), or native RDP agent (configurable options)

Support multiple screens, local printing

Security control option to limit copy-paste and printing

Configurable RDP security mode and authentication

Agentless RDP with dynamic access control

Use a single access rule, to establish a dynamic access policy that determines which specific RDP host is assigned to each user, based on IDP attribute

Agentless VNC access  Web interface

Agentless SSH access  Web interface

Device posture validation checks  Endpoint Security, Certificate, Disk Encryption, File exists, registry key, process running, windows security center, domain membership

Posture validation profiles  Multiple profiles, support all OSs

Continuous validation  Yes, configurable intervals

Additional Zero Trust validations 
 (access context)

Geo-location, Date and Time, OS, Browser

DNS filtering  Cloud resolver with DNS filtering

Firewall  Identity-based Firewall-as-a-Service

Secure Internet Access

Malware protection  Scan all downloaded files and web components

Sandbox protection  Utilizing Check Point Threat Emulation technology and ThreatCloud AI

Content Disarm and Reconstruction (CDR)  Utilizing Check Point Threat Extraction technology and ThreatCloud AI

Zero-day phishing protection  Utilizing Check Point Zero-Phishing technology and ThreatCloud AI

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 11

Check Point SASE Feature Overview

Feature Description

Zero Trust Network Access / Private Access

Network access Supports all protocols, full mesh access in any direction, all connections subject to policy with posture and identity

Agentless web access  Supported with reverse proxy, option for URL alias and customer certificate

Agentless enterprise browser  Zero Trust access for unmanaged devices with corporate data sandboxing and DLP protections including session recording and watermarking

Agentless RDP access  Web Interface (HTML RDP), or native RDP agent (configurable options)  Support multiple screens, local printing  Security control option to limit copy-paste and printing  Configurable RDP security mode and authentication

Agentless RDP with dynamic access control

Use a single access rule, to establish a dynamic access policy that determines which specific RDP host is assigned to each user, based on IDP attribute

Agentless VNC access  Web interface

Agentless SSH access  Web interface

Device posture validation checks  Endpoint Security, Certificate, Disk Encryption, File exists, registry key, process running, windows security center, domain membership

Posture validation profiles  Multiple profiles, support all OSs

Continuous validation  Yes, configurable intervals

Additional Zero Trust validations (access context)

Geo-location, Date and Time, OS, Browser

DNS filtering  Cloud resolver with DNS filtering

Firewall  Identity-based Firewall-as-a-Service

Secure Internet Access

Malware protection  Scan all downloaded files and web components

Sandbox protection  Utilizing Check Point Threat Emulation technology and ThreatCloud AI

Content Disarm and Reconstruction (CDR)  Utilizing Check Point Threat Extraction technology and ThreatCloud AI

Zero-day phishing protection  Utilizing Check Point Zero-Phishing technology and ThreatCloud AI

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 12

Feature Description

Secure Internet Access

URL reputation protection  Utilizing Check Point Anti-Bot and ThreatCloud AI

URL filtering   Utilizing Check Point's URL categorization with 110 categories

HTTPS inspection  Yes

Workforce AI Security

Prevent Data Leakage 
 (DLP Data type manager)

Centralized data type and policy management across all AI interactions. Inline detection in prompts, uploads, and pastes. Real-time redaction with labeled placeholders. Actions: Allow, Ask, Block, Prevent, Detect, Redact

AI Security for Web AI apps  Discovery, governance, and DLP for web-based AI applications. Catalog of 4,000+ GenAI apps. Per-app policies for prompts, copy/paste, and file uploads. Session-level visibility and user intent classification

Managed (enterprise) / Unmanaged (private) AI apps

Separate policy enforcement for sanctioned enterprise tenants vs. personal or unsanctioned instances of the same application

AI Security for Desktop AI apps  Extends discovery, governance, and DLP to locally installed AI applications and assistants. Same policy model as web-based AI apps

AI Security for Code Assistance (IDEs)  Coverage for IDE-integrated AI coding assistants. Detection and redaction of secrets, credentials, and source code in prompts and outputs

AI Security for Agents (MCPs connected to corporate resources)

Inspection of MCP and agent traffic. Runtime policies define permitted tools, operations, and platforms per agent. Blocks unsafe autonomous actions against corporate resources

Inventory Endpoint Scanner for Agents including risk assessment

Endpoint scanning for installed AI agents and assistants. Per-agent metadata: vendor, model, identity, environment. Risk assessment flags risky models, non-organizational identity use, and human-in-the-loop status

Compliance reporting  Audit trails and customizable reports for GDPR, HIPAA, and EU AI Act

DLP

Predefined data types  800+ including PCI, PII, HIPAA, source code and many more

Supported data object types  Pattern, Keyword, Dictionary, Weighted Words, Template, File attribute, Exact data match, Document fingerprint

Microsoft Purview sensitivity labels  Supported

OCR analysis   Supported

Cloud Service

SLA  99.999%

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 12

Feature Description

Secure Internet Access

URL reputation protection  Utilizing Check Point Anti-Bot and ThreatCloud AI

URL filtering   Utilizing Check Point's URL categorization with 110 categories

HTTPS inspection  Yes

Workforce AI Security

Prevent Data Leakage (DLP Data type manager)

Centralized data type and policy management across all AI interactions. Inline detection in prompts, uploads, and pastes. Real-time redaction with labeled placeholders. Actions: Allow, Ask, Block, Prevent, Detect, Redact

AI Security for Web AI apps  Discovery, governance, and DLP for web-based AI applications. Catalog of 4,000+ GenAI apps. Per-app policies for prompts, copy/paste, and file uploads. Session-level visibility and user intent classification

Managed (enterprise) / Unmanaged (private) AI apps

Separate policy enforcement for sanctioned enterprise tenants vs. personal or unsanctioned instances of the same application

AI Security for Desktop AI apps  Extends discovery, governance, and DLP to locally installed AI applications and assistants. Same policy model as web-based AI apps

AI Security for Code Assistance (IDEs)  Coverage for IDE-integrated AI coding assistants. Detection and redaction of secrets, credentials, and source code in prompts and outputs

AI Security for Agents (MCPs connected to corporate resources)

Inspection of MCP and agent traffic. Runtime policies define permitted tools, operations, and platforms per agent. Blocks unsafe autonomous actions against corporate resources

Inventory Endpoint Scanner for Agents including risk assessment

Endpoint scanning for installed AI agents and assistants. Per-agent metadata: vendor, model, identity, environment. Risk assessment flags risky models, non-organizational identity use, and human-in-the-loop status

Compliance reporting  Audit trails and customizable reports for GDPR, HIPAA, and EU AI Act

DLP

Predefined data types  800+ including PCI, PII, HIPAA, source code and many more

Supported data object types  Pattern, Keyword, Dictionary, Weighted Words, Template, File attribute, Exact data match, Document fingerprint

Microsoft Purview sensitivity labels  Supported

OCR analysis   Supported

Cloud Service

SLA  99.999%

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 13

Feature Description

Cloud Service

Cloud Points-of-Presence (PoPs)  80+ global PoPs, privately owned

Cloud backbone  Private backbone consisting of at least dual tier-1 providers at each PoP for fast connectivity across our network

Multiple cloud networks per customer  Support for multiple networks per account for more flexible network architectures and faster M&A consolidation

Full mesh connectivity in any direction  Full mesh cloud-based networking enables seamless private access connectivity in any direction (e.g. data center to branch, branch to user, etc.)

Network-to-Site connection  Connect from any device using IPsec, or connect with Connector software

Network-to-Site protocols  IPsec IKEv1, IPsec IKEv2, Wireguard, OpenVPN

Redundancy  Support for redundant tunnels to separate availability zones or regions

User-to-Site protocols  Agent: Wireguard, OpenVPN

Dedicated cloud IP per customer  Standard for all customers, enables IP-whitelisting for Zero Trust access to SaaS

SD-WAN integration  Integrated with Check Point SD-WAN. 
 Connect with 3rd party SD-WAN via IPsec

Dynamic Routing  Yes, using BGP

Data residency  United States, European Union

SASE Agent

Supported platforms  Mac, Windows, Linux, iOS, Android, Chromebook

On-device network security - Hybrid SASE

Network security controls for Internet Access (SWG) are enforced within the agent (optional), and subject to customer policy, are routed directly to the internet service without cloud routing. 
 This capability enables users to experience their native internet speed and delivers internet performance that is double that of traditional SSE/SWG services which force all traffic through the cloud.

Split tunnelling  Yes

Disconnect when in trusted networks  Yes

Connection protocol  Wireguard or OpenVPN - configurable

Prevent user sign-out  Yes, option to issue one-time disconnect code

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 13

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Feature Description

Cloud Service

Cloud Points-of-Presence (PoPs)  80+ global PoPs, privately owned

Cloud backbone  Private backbone consisting of at least dual tier-1 providers at each PoP for fast connectivity across our network

Multiple cloud networks per customer  Support for multiple networks per account for more flexible network architectures and faster M&A consolidation

Full mesh connectivity in any direction  Full mesh cloud-based networking enables seamless private access connectivity in any direction (e.g. data center to branch, branch to user, etc.)

Network-to-Site connection  Connect from any device using IPsec, or connect with Connector software

Network-to-Site protocols  IPsec IKEv1, IPsec IKEv2, Wireguard, OpenVPN

Redundancy  Support for redundant tunnels to separate availability zones or regions

User-to-Site protocols  Agent: Wireguard, OpenVPN

Dedicated cloud IP per customer  Standard for all customers, enables IP-whitelisting for Zero Trust access to SaaS

SD-WAN integration  Integrated with Check Point SD-WAN.  Connect with 3rd party SD-WAN via IPsec

Dynamic Routing  Yes, using BGP

Data residency  United States, European Union

SASE Agent

Supported platforms  Mac, Windows, Linux, iOS, Android, Chromebook

On-device network security - Hybrid SASE

Network security controls for Internet Access (SWG) are enforced within the agent (optional), and subject to customer policy, are routed directly to the internet service without cloud routing.  This capability enables users to experience their native internet speed and delivers internet performance that is double that of traditional SSE/SWG services which force all traffic through the cloud.

Split tunnelling  Yes

Disconnect when in trusted networks  Yes

Connection protocol  Wireguard or OpenVPN - configurable

Prevent user sign-out  Yes, option to issue one-time disconnect code

Check Point SASE | 14

Feature Description

SASE Agent

Connect on launch  Yes, Configurable

Connection notification  Yes, Configurable

Control agent upgrade  Yes, Configurable per OS

Automatic Wi-Fi security  Yes, Configurable

Automatic log-out  Configurable

Identity Management

Supported IDPs  Microsoft Entra ID, Okta, Google Workspace, Active Directory, Generic SAML (OneLogin, JumpCloud, etc.)

Authentication  SAML 2.0

Identity Management  SCIM

Multiple IDPs  Yes

Local user database  Yes

Reset user password  Yes

SaaS API Security

SaaS application catalog  130,000+ SaaS applications including 4,000+ GenAI applications. Display per application: Name, Description, Publisher/Vendor, Category, Website, Risk Assessment, Certification, Privacy Policy, Terms

SaaS application discovery  Discovered SaaS applications are categorized, monitored and assigned a risk score

SaaS visibility and monitoring  Extensive reporting covering services, integrations, users, and tokens, with actionable insights and recommendations

SaaS Anomaly Detection   Yes

Supported SaaS apps: Threat Prevention and SSPM

Asana, Atlassian, AWS, BambooHR, Bitbucket, Box, Dropbox, Freshdesk, GitHub, GitLab, Google Workspace, HubSpot, Jira, Microsoft OneDrive, Microsoft SharePoint, Microsoft Teams, Monday, Okta, OneLogin, Ping Identity, Salesforce, ServiceNow, Slack, Smartsheet, Zendesk, Zoom

Out-of-Band (API) DLP  API-based scanning of data at rest across SaaS platforms. Detects sensitive data in files, messages, and unstructured content (e.g., Jira tickets, Teams and Slack messages). Over-sharing protection with continuous permission scanning and automatic remediation. AI-powered classification with 800+ predefined data types.

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 14

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Feature Description

SASE Agent

Connect on launch  Yes, Configurable

Connection notification  Yes, Configurable

Control agent upgrade  Yes, Configurable per OS

Automatic Wi-Fi security  Yes, Configurable

Automatic log-out  Configurable

Identity Management

Supported IDPs  Microsoft Entra ID, Okta, Google Workspace, Active Directory, Generic SAML (OneLogin, JumpCloud, etc.)

Authentication  SAML 2.0

Identity Management  SCIM

Multiple IDPs  Yes

Local user database  Yes

Reset user password  Yes

SaaS API Security

SaaS application catalog  130,000+ SaaS applications including 4,000+ GenAI applications. Display per application: Name, Description, Publisher/Vendor, Category, Website, Risk Assessment, Certification, Privacy Policy, Terms

SaaS application discovery  Discovered SaaS applications are categorized, monitored and assigned a risk score

SaaS visibility and monitoring  Extensive reporting covering services, integrations, users, and tokens, with actionable insights and recommendations

SaaS Anomaly Detection   Yes

Supported SaaS apps: Threat Prevention and SSPM

Asana, Atlassian, AWS, BambooHR, Bitbucket, Box, Dropbox, Freshdesk, GitHub, GitLab, Google Workspace, HubSpot, Jira, Microsoft OneDrive, Microsoft SharePoint, Microsoft Teams, Monday, Okta, OneLogin, Ping Identity, Salesforce, ServiceNow, Slack, Smartsheet, Zendesk, Zoom

Out-of-Band (API) DLP  API-based scanning of data at rest across SaaS platforms. Detects sensitive data in files, messages, and unstructured content (e.g., Jira tickets, Teams and Slack messages). Over-sharing protection with continuous permission scanning and automatic remediation. AI-powered classification with 800+ predefined data types.

Check Point SASE | 15

Feature Description

SaaS API Security

Out-of-Band (API) Threat Prevention  API-based malware scanning of data at rest across SaaS environments, powered by ThreatCloud AI. Detects and remediates known and unknown threats with automated response.

Supported SaaS apps: DLP and Threat Prevention

Google Workspace, Jira, Salesforce, Microsoft (OneDrive, SharePoint, Teams), Dropbox, Box, Slack, GitHub

SaaS Security

SaaS Application Control  Identifies and manages access to 10,000+ cloud applications with granular allow, block, or restrict actions based on corporate policy

Tenant Restrictions  Limits access to sanctioned organizational SaaS tenants only, preventing login to personal or unauthorized instances (Microsoft 365 and Google Workspace)

Inline DLP  Real-time inspection of uploads and downloads across web and SaaS traffic using AI- powered classification with 800+ predefined data types

Inline Threat Prevention  Scans downloads and web content for known and unknown malware, powered by ThreatCloud AI

Logs and reports

Log retention  3 months by default, extended period available at an additional cost

Event forwarding to SIEM  Supported using syslog

Activity monitoring  Active sessions, User activity, Web and remote access and threat prevention, Audit Logs

Certification

SOC2 Type 2 Compliance  Certified

ISO 27001, ISO 27002  Certified

ISO 9001  Certified

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Check Point SASE | 15

Requires the following license: (1) Browser security. (2) SaaS security. (3) Collaboration security.

Feature Description

SaaS API Security

Out-of-Band (API) Threat Prevention  API-based malware scanning of data at rest across SaaS environments, powered by ThreatCloud AI. Detects and remediates known and unknown threats with automated response.

Supported SaaS apps: DLP and Threat Prevention

Google Workspace, Jira, Salesforce, Microsoft (OneDrive, SharePoint, Teams), Dropbox, Box, Slack, GitHub

SaaS Security

SaaS Application Control  Identifies and manages access to 10,000+ cloud applications with granular allow, block, or restrict actions based on corporate policy

Tenant Restrictions  Limits access to sanctioned organizational SaaS tenants only, preventing login to personal or unauthorized instances (Microsoft 365 and Google Workspace)

Inline DLP  Real-time inspection of uploads and downloads across web and SaaS traffic using AI- powered classification with 800+ predefined data types

Inline Threat Prevention  Scans downloads and web content for known and unknown malware, powered by ThreatCloud AI

Logs and reports

Log retention  3 months by default, extended period available at an additional cost

Event forwarding to SIEM  Supported using syslog

Activity monitoring  Active sessions, User activity, Web and remote access and threat prevention, Audit Logs

Certification

SOC2 Type 2 Compliance  Certified

ISO 27001, ISO 27002  Certified

ISO 9001  Certified

Check Point SASE | 16

Unified SASE Architecture

Optimizing Security and Connectivity

Remote
 User

On-Device Protection

Web

SaaS

Offices

SD-WAN

Private
 Access

SaaS
 Security

Internet
 Access

SD-WAN

Cloud
 Workloads

On-Prem
 Datacenter

Discover Check Point SASE

Don’t compromise on an excellent user experience to secure your shift to hybrid and cloud.

Book a Demo

www.checkpoint.com  © 2026 Check Point Software Technologies Ltd. All rights reserved.

Check Point SASE | 16

Unified SASE Architecture Optimizing Security and Connectivity

Discover Check Point SASE  Don't compromise on an excellent user experience to secure your shift to hybrid and cloud.

www.checkpoint.com  © 2026 Check Point Software Technologies Ltd. All rights reserved.

SD-WAN SD-WAN

On-Device Protection

Remote User

Offices

Web

SaaS

Cloud Workloads

On-Prem Datacenter

Private Access

SaaS Security

Internet Access

https://sase.checkpoint.com/demo?utm_source=cp&utm_medium=PDF&utm_campaign=harmony https://www.checkpoint.com


Item Type: pdf